logo

Authorities released free decryptor for Phobos and 8base ransomware

ID: d3b8ba68-6746-587e-8c51-fabe00630308

STIX ID: report--d3b8ba68-6746-587e-8c51-fabe00630308

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2025-07-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Japanese police published a free decryptor for Phobos and 8Base ransomware (available via the police site and NoMoreRansom), enabling victims to recover files encrypted by extensions such as .phobos, .8base, .elbie, .faust, and .LIZARD; authorities warn to remove malware before decrypting. The report also details Phobos/8Base as RaaS operations active since 2019/2022, their use of phishing, RDP access, Smokeloader, Cobalt Strike and Bloodhound, and law enforcement actions including extraditions and unsealed charges tied to significant extortion activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.